A practice’s second outsourcing decision is always made differently from its first. The first time, it usually buys a pitch: a tidy deck, a stack of CVs with CA and ACCA after the names, a price per head, and a promise of a five-day turnaround. Month one goes well. By month four, the preparer on the account has changed twice, suspense balances are creeping up on three clients, and queries come back answered but not resolved. Then, the week before a VAT deadline, the team is suddenly thin. When a partner asks who checked the files before they were sent, nobody can give a straight answer.
None of that was hidden. It just wasn’t asked. Most due diligence on UK accounting outsourcing companies in India tests the sales process rather than the delivery process. It checks badges, CVs, and a price, instead of who does the work, who checks it, what happens when they’re away, and what the contract says about your clients’ data.
We’re one of the companies you’d be assessing. Probal Global has supported UK accountancy firms from India since 2017, so this is written from the supplier’s side of the table, and you should read it with that in mind. It’s the checklist we’d want a practice to use on us, including the questions that make weaker providers uncomfortable.
It covers six operational checks, the data protection terms your contract needs, what a reviewer-ready file should contain, the questions that separate a practice partner from a body shop, how to run a trial that proves something, and what’s changed in 2026. At the end, we answer our own checklist.
The due diligence checklist, area by area
Six areas decide whether an arrangement still works in month twelve. For each one, look for evidence rather than assurance.
1. UK experience, not just qualifications
A CA, ACCA or CMA qualification tells you someone understands accounting. It doesn’t tell you they understand a UK practice file, and the gap shows up wherever UK judgement is needed: VAT schemes and the domestic reverse charge, CIS, PAYE and RTI, director’s loan accounts, FRS 102 and FRS 105 disclosures, iXBRL tagging and CT600 computations.
Ask how many years each named team member has spent on UK files, not how long they’ve been qualified. Ask whether that experience is with UK practices or UK businesses, because working to a reviewer’s standards is a skill of its own. A good test right now is the FRS 102 periodic review, which applies to accounting periods beginning on or after 1 January 2026 and brings most leases onto lessees’ balance sheets. A team with current UK experience will already be planning for the first December 2026 year-ends it affects. Then ask to see anonymised work, and read the working papers as closely as the numbers.
2. Software coverage across your whole stack
Most providers list Xero, QuickBooks and Sage. Fewer are genuinely fluent across the rest of a practice’s stack: FreeAgent for bookkeeping, IRIS, TaxCalc and CCH for accounts production and tax, and whatever you run for payroll. Coverage matters because a provider that only works in cloud ledgers pushes your accounts production, tax and payroll back onto your own team.
Ask which named people use each product every week, not which products the company has touched. Check partner status in the vendor’s own partner or advisor directory rather than relying on a logo.
For desktop and hosted products, ask how access works: remote desktop into your environment, a hosted server, or files sent back and forth. The last is the weakest from a security point of view. It’s also worth checking that your own licence terms allow access by a third party working outside the UK.
3. A security posture you can verify
“Secure” is a claim, so ask for the controls behind it: multi-factor authentication on every system, access limited to named people, no local downloads or personal devices, blocked USB storage, encrypted transfer, logging, and a documented process for removing access the day someone leaves. Ask how staff are vetted and what confidentiality agreements they sign individually.
Certifications help, but read them properly. ISO 27001 is the usual benchmark, and there’s a real difference between a provider that is certified and one whose controls are aligned to the standard. Certified means an accredited certification body has audited the system. Aligned means the provider has built its controls around the standard without that external audit. Both are honest descriptions when used accurately.
If a provider says certified, ask for the certificate and check the issuing body, the scope and the expiry date. Check the version too. Certificates against the 2013 edition stopped being valid after 31 October 2025, and current certificates reference the 2022 edition, which has 93 controls. Treat “GDPR certified” with caution as well: the ICO explains that UK GDPR certification comes only through ICO-approved schemes run by accredited certification bodies.
4. Working hours and UK bank holiday alignment
India is four and a half hours ahead of the UK during British Summer Time, and five and a half hours ahead once the clocks go back on 25 October. Ask what shift pattern your team works, how many hours overlap with your office, and who picks up the phone if something goes wrong at 4pm UK time.
Then ask about holidays in both directions. UK bank holidays differ between England and Wales, Scotland and Northern Ireland, so agree whether the team works or observes them.
Indian holidays matter just as much, because some land on UK deadlines. Diwali falls on 8 November this year, with celebrations running from 6 to 10 November, directly across the 7 November deadline for September-quarter VAT returns and MTD for Income Tax quarterly updates. Republic Day on 26 January sits in the final week of self assessment season. A provider that has planned for both will show you the cover rota before you ask.
5. Escalation routes that work under pressure
Every provider has an account manager. What matters is what happens when the account manager isn’t the answer. Ask for the escalation matrix in writing. It should show who you contact for a query, a missed deadline, a quality complaint and a suspected data incident, how quickly each should respond, and who sits above them. Check whether there’s a UK-hours phone line and whether a senior person can be reached during your deadline weeks.
Then test it. During a trial, raise one deliberate escalation and time the response. A provider that only works through a shared inbox will show you that quickly.
6. Quality review layers before work reaches you
Ask exactly who reviews a file before it’s sent to you, how senior they are, and what they check against. A credible answer names a preparer and a separate reviewer, a checklist for each type of job, and a log of the corrections your team makes so the same error isn’t repeated. Ask whether the provider tracks rework and turnaround, and whether it will share those figures with you every month.
Be honest about your side too. If your own review process was loose before you outsourced, offshore production will expose that rather than fix it. Your reviewer still signs off. The provider’s review is there to make that sign-off quicker, not unnecessary.
NDA, data processing terms and GDPR processor obligations
An NDA on its own isn’t enough. It covers confidentiality, but UK GDPR asks for something more specific. When a provider handles client personal data on your behalf, it acts as your processor, and Article 28 requires a written contract with set terms. The ICO’s guidance on controller-processor contracts sets out what that contract must cover:
- Documented instructions. The provider processes data only on your written instructions.
- Confidentiality. Everyone handling the data is bound by a duty of confidence.
- Security. Appropriate technical and organisational measures, as Article 32 requires.
- Sub-processors. None without your prior written authorisation, with the same obligations passed down and the provider liable for them.
- Individuals’ rights. Help with subject access and other requests.
- Breaches and assessments. Help with security, breach notification and impact assessments. Under Article 33, the provider must tell you about a breach without undue delay.
- Exit. Deletion or return of all personal data when the contract ends, at your choice.
- Audit. The information you need to show compliance, and cooperation with audits and inspections.
Beyond the statutory terms, look for non-solicitation of your clients and staff, ownership of your process notes and working papers, insurance, governing law and a written exit plan.
Because the data leaves the UK, you also need a transfer mechanism. India isn’t covered by UK adequacy regulations, so the usual route is the ICO’s International Data Transfer Agreement, or the UK Addendum to EU standard contractual clauses, backed by a transfer risk assessment. The ICO updated its international transfers guidance in January 2026, and new rules on transfer risk assessments took effect on 5 February 2026.
Two Indian points belong in that assessment. First, India’s Digital Personal Data Protection Act largely exempts Indian firms processing non-residents’ data under a foreign contract from its main duties, leaving mainly the obligation to keep that data secure. In practice, your contract does most of the protective work, so make it specific. Second, organisations in India must report certain cyber incidents to CERT-In, the national response team, within six hours of noticing them. Ask how the provider’s incident process fits around that, and when you’ll be told.
What a reviewer-ready deliverable should contain
“Reviewer-ready” is the phrase every provider uses, so define it before you sign. For a monthly bookkeeping file, we’d expect:
- Reconciliations that tie. Every bank, card and loan account reconciled to its statement, with the statement attached.
- Control accounts agreed. VAT, PAYE, CIS, pension and director’s loan balances agreed to their source.
- A cleared or explained suspense account. Nothing parked without a note.
- Aged debtors and creditors reviewed. Old items flagged rather than carried forward silently.
- A journal list with reasons. Every manual journal with a short explanation and its support.
- A query log. Open questions for the client, each with the evidence behind it.
- A short commentary. Unusual movements and judgement calls, so your reviewer knows where to look first.
For year-end accounts, add a trial balance with lead schedules, working papers cross-referenced to source, fixed asset and accruals schedules, a director’s loan account analysis, a completed FRS 102 or FRS 105 disclosure checklist, and a list of review points already cleared. For CT600 returns, add the computation, capital allowances workings and supporting schedules. If your reviewer has to rebuild any of that, the file wasn’t ready.
The questions that separate a practice partner from a body shop
Outsourced accounting firms tend to fall into two camps. A body shop sells hours and CVs. A practice partner sells a working process that happens to include people. These questions tell them apart quickly.
| Ask this | A practice partner will | A body shop will |
| Who will work on our files each month? | Name them and keep them, with a named backup | Offer a pool and a CV |
| Who reviews work before we see it? | Name a separate, more senior reviewer and show the checklist | Say quality is checked |
| What happens when our person is on leave or leaves? | Show the cover rota, handover notes and replacement timescales | Promise to find someone |
| Can we see a real reviewer-ready file? | Share an anonymised example | Share a brochure |
| Will you sign a data processing agreement and an IDTA? | Review them and agree terms | Offer an NDA instead |
| Who can access our clients’ data, and from where? | Name the roles, systems and controls | Say it’s secure |
| How do you measure quality? | Explain how errors are counted and share the figures | Give a headline number with no method |
| Will you ever contact HMRC or our clients? | Agree a written position with you | Say whatever you need |
| What does the exit look like? | Describe data return, deletion and handover | Point to the notice period |
| Can we trial on real, awkward files? | Encourage it | Suggest a sample job of their choosing |
Dedicated staffing isn’t the problem in itself, and a body shop isn’t always cheaper. The problem is buying people without the process around them.
Running a trial that proves something
Most trials fail as tests because the practice sends its easiest files. Use the trial to find out what month six will look like.
Send awkward files. Include one client with messy records, one on desktop software and one with a VAT or CIS complication.
Time your review. Record how long your reviewer spends on each file and what they change. That number is the real measure of quality.
Test the query loop. Check whether queries are specific, evidenced and grouped, or scattered across a dozen emails.
Escalate once on purpose. Raise a problem through the escalation route, and note who responds and how fast.
Ask for the full deliverable. Judge the working papers and commentary, not just the numbers.
Check security in practice. Watch how files move, who has access and what happens to downloads.
Run through a deadline. If you can, include a VAT quarter-end or a holiday week, when weaker teams go thin.
If you’re unsure which workflows to start with, our guide to which workflows should leave your practice first is a practical starting point.
What changes in 2026 for practices using offshore teams
Four developments this year change what good due diligence looks like.
Mandatory tax adviser registration. Under the Finance Act 2026, firms that interact with HMRC about a client’s tax affairs must register with HMRC, and the regime applies to non-UK advisers too. ICAEW’s summary sets out the timetable, which began on 18 May 2026. If a provider will ever call HMRC or file anything itself, ask whether it’s registered. Most practices keep every HMRC interaction under their own agent services account.
Companies House identity verification and filing. Existing directors and people with significant control must complete identity verification by 18 November 2026. Companies House also plans to limit third-party filing to registered Authorised Corporate Service Providers, from no earlier than November 2026. ACSP registration depends on UK anti-money laundering supervision, so in practice filing stays with your firm. A provider can prepare the company secretarial work; your firm submits it.
New data transfer rules. The ICO’s January 2026 guidance, and the transfer risk assessment rules in force since 5 February 2026, mean transfer paperwork signed before then deserves a second look.
New UK GAAP. The FRS 102 and FRS 105 changes for periods beginning on or after 1 January 2026 will reach accounts production from early 2027. They’re the clearest current test of whether a provider’s UK training is up to date.
Frequently asked questions
How do I choose between accounting outsourcing companies in India?
Shortlist on evidence rather than presentation. Check named-team UK experience, software fluency across your stack, verifiable security controls, a proper data processing agreement and transfer mechanism, a written escalation route and a separate review layer. Then trial on real, awkward files and time your own review. The provider that makes your reviewer’s job shortest is usually the right one.
Is it safe to outsource accounting to India?
It can be, when the controls and contract are right. Safety comes from access restricted and logged to named people, no local storage, encryption, vetted staff, and a contract that meets UK GDPR processor requirements with a valid transfer mechanism. Ask to see each of those rather than accepting a general assurance.
Is outsourcing to India compliant with UK GDPR?
Yes, when it’s set up properly. You need an Article 28 data processing agreement, a transfer mechanism such as the ICO’s International Data Transfer Agreement, and a transfer risk assessment, because India isn’t covered by UK adequacy regulations. Your privacy notice should also tell clients that their data may be processed outside the UK.
What’s the difference between an NDA and a data processing agreement?
An NDA protects confidential information in general. A data processing agreement sets out the specific duties UK GDPR places on a processor handling personal data for you: following your instructions, security, sub-processors, breach support, deletion and audits. Outsourcing client work needs both, plus a transfer mechanism when the data leaves the UK.
What does ISO 27001 aligned mean, compared with certified?
Aligned means a provider has built its security controls around the ISO 27001 framework. Certified means an accredited certification body has audited those controls and issued a certificate with a defined scope and expiry date. Both are legitimate positions when described accurately. If a provider says certified, ask for the certificate and check it references the 2022 edition.
Are Indian accountants qualified to prepare UK accounts?
Many hold strong qualifications such as CA, ACCA or CMA. The qualification matters less than UK-specific experience with VAT, CIS, PAYE, FRS 102 and FRS 105, iXBRL and CT600 work. Ask how long each named person has worked on UK practice files, and test them on your own.
Do I need to tell my clients that I use an outsourcing company?
We’d say yes. Confidentiality is a fundamental principle in the ICAEW Code of Ethics, and ICAEW’s test is whether a client would reasonably expect their information to be shared that way. ACCA’s engagement letter guidance also makes clear that you stay responsible for confidentiality when work is outsourced. A clear engagement letter clause and privacy notice deal with it.
Who is responsible if the outsourced team makes a mistake?
Your firm, as far as your client is concerned. The provider contract should cover error correction at the provider’s cost, confidentiality, insurance and breach handling. Keep your own review and sign-off on everything that leaves the practice, and check that your professional indemnity cover reflects how the work is now delivered.
How can I check an outsourcing company is legitimate?
Confirm the legal entity you’ll contract with. Some accounting outsourcing firms in the UK deliver the work from India through a UK-facing entity, so check who signs the contract and where the work is done. Indian companies and LLPs appear on the Ministry of Corporate Affairs register, and any UK entity will be on Companies House. Ask for references from UK practices of a similar size, verify certificates with the issuing body, and ask for a live video walkthrough of the working environment. A provider with nothing to hide won’t mind.
What should happen to our data when the contract ends?
Your data processing agreement should require the provider to delete or return all personal data at the end, at your choice, and to confirm it in writing. Agree an exit plan at the start, covering the handover of working papers and process notes, removal of system access, and the timescale for deletion.
What are the red flags when choosing an outsourcing provider?
A rotating pool instead of named people, no separate reviewer, an NDA offered in place of a data processing agreement, and vague answers about who can access data. Also watch for certificates that can’t be produced or still show ISO 27001:2013, quality claims with no evidence behind them, and reluctance to trial on your real files.
Judge us by the same list
Everything in this checklist applies to us, so here’s how we answer it. Where the answer is a document, ask us for the document rather than relying on our description.
| Check | Our position |
| UK experience | Supporting UK accountancy firms since 2017. Our team includes Chartered Accountants and professionals with at least three years of UK accounting experience |
| Named team | Named team members on every engagement, with a dedicated account manager |
| Software | Xero, QuickBooks, Sage and FreeAgent, plus IRIS, TaxCalc, CCH, BTCSoftware, Capium and BrightPay |
| Security controls | NDA before any data access, role-restricted access, MFA, no personal device storage, encrypted transfers, dedicated client file environments and regular internal security audits |
| ISO 27001 | Controls aligned to ISO 27001 [CONFIRM: aligned or certified; if certified, add the certification body, scope and expiry date] |
| Data processing terms | [CONFIRM: for example, “We sign an Article 28 data processing agreement and an IDTA. Ask us for both.”] |
| Working hours | Aligned with UK bank holidays, and team members can join your calls [CONFIRM: shift hours and the cover plan for Diwali week] |
| Quality review | Every file reviewed before it leaves us [CONFIRM: preparer and reviewer structure] |
| Turnaround | Five working days on standard jobs |
| Onboarding | Operational within two to three working days of the brief and signed agreement |
| Escalation | [CONFIRM: escalation matrix and response times] |
| HMRC and client contact | [CONFIRM: your written position] |
If you’d like to see the paperwork behind any of that, talk to our team. You can read more about who we are and the accounting outsourcing services we provide to UK practices, or test everything above on your own files with a free trial.
Related reading: Outsourced accounting services UK: a practice owner’s guide | Which workflows should leave your practice first | Outsourced bookkeeping rates UK
This article is general guidance for UK accountancy practices and is not legal advice. Data protection, tax agent, and Companies House requirements are changing during 2026; the position described is as at publication. Take specialist advice on your own contracts and transfer risk assessment.
Need help outsourcing this to a specialist team?
We handle bookkeeping, VAT, payroll, and year end accounts for UK accounting firms from India. Start with a free trial. No commitment required.




